Unrestricted File Upload Vulnerability in Baggage Freight Shipping Plugin for WordPress
CVE-2018-25436
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 15 June 2026
Badges
What is CVE-2018-25436?
The Baggage Freight Shipping Plugin for WordPress version 0.1.0 is susceptible to an arbitrary file upload vulnerability caused by inadequate validation of uploaded files through the upload-package.php endpoint. This flaw permits unauthenticated attackers to remotely upload malicious files to the server. By sending specially crafted POST requests, attackers can exploit this vulnerability to execute arbitrary code, potentially compromising the entire WordPress installation.
Affected Version(s)
Baggage Freight Shipping Australia 0.1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved